CVE-2018-8584
HIGHWindows 10 and Windows Server 2016/2019 - Elevation of Privilege via ALPC
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-8584. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit leverages a TOCTOU (Time-of-Check Time-of-Use) vulnerability in the Data Sharing Service (DSSVC) on Windows 10 1803/1809, allowing arbitrary file deletion due to improper handling of file permissions in PolicyChecker::CheckFilePermission. The PoC demonstrates this by exploiting per-user drive redirection to delete files inaccessible to the user but accessible to SYSTEM.
Description
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
Exploits (1)
The exploit leverages a TOCTOU (Time-of-Check Time-of-Use) vulnerability in the Data Sharing Service (DSSVC) on Windows 10 1803/1809, allowing arbitrary file deletion due to improper handling of file permissions in PolicyChecker::CheckFilePermission. The PoC demonstrates this by exploiting per-user drive redirection to delete files inaccessible to the user but accessible to SYSTEM.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H